package com.jtg.security.controller;

import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

@RestController
@RequestMapping("/user")
public class UserController {

    /**
     * 权限使用注解，user角色可访问
     *
     * @return
     */
    @GetMapping("/index")
    @PreAuthorize("hasAuthority('user')")
    public String index() {
        return "用户首页";
    }
}
